Windows-APT 2025 Dataset
Host and network telemetry from 36 APT-inspired attack scenarios on Windows systems, mapped to the MITRE ATT&CK framework.
Published February 2026 in Data in Brief by Cyber Science Lab researchers Maryam Mozaffari, Abbas Yazdinejad, and Ali Dehghantanha. Addresses the shortage of realistic, richly-labelled telemetry for studying advanced persistent threat (APT) behaviour on Windows systems.
Introduction
The dataset recreates 36 APT-inspired attack scenarios drawn from MITRE ATT&CK threat-actor profiles inside a controlled Windows 10 environment, using the MITRE Caldera adversary-emulation framework to generate the underlying activity.
Dataset details
Host and network activity was captured with Wazuh and Sysmon and systematically mapped back to MITRE ATT&CK techniques, producing roughly 102,000 log records across 19 CSV files — multi-source telemetry suited to training and evaluating machine-learning-based intrusion detection systems.
Citation
Mozaffari, M., Yazdinejad, A., & Dehghantanha, A. (2026). Windows-APT 2025: A dataset for APT-inspired attack scenarios on windows systems. Data in Brief, 65, 112569. DOI: 10.1016/j.dib.2026.112569.
Download
The dataset is available on Mendeley Data under a CC BY 4.0 license.
